Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| lodash | lodash | 4.17.20 | - |
| oracle | banking_corporate_lending_process_management | - | - |
| oracle | banking_corporate_lending_process_management |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
42
Affected Products
16
References
lodash / lodash
| - |
| - |
| oracle | banking_corporate_lending_process_management | - | - |
| oracle | banking_credit_facilities_process_management | - | - |
| oracle | banking_credit_facilities_process_management | - | - |
| oracle | banking_credit_facilities_process_management | - | - |
| oracle | banking_extensibility_workbench | - | - |
| oracle | banking_extensibility_workbench | - | - |
| oracle | banking_extensibility_workbench | - | - |
| oracle | banking_liquidity_management | - | - |
| oracle | banking_liquidity_management | - | - |
| oracle | banking_liquidity_management | - | - |
| oracle | banking_supply_chain_finance | - | - |
| oracle | banking_supply_chain_finance | - | - |
| oracle | banking_supply_chain_finance | - | - |
| oracle | banking_trade_finance_process_management | - | - |
| oracle | banking_trade_finance_process_management | - | - |
| oracle | banking_trade_finance_process_management | - | - |
| oracle | banking_virtual_account_management | - | - |
| oracle | banking_virtual_account_management | - | - |
| oracle | banking_virtual_account_management | - | - |
| oracle | blockchain_platform | 21.1.2 | - |
| oracle | communications_billing_and_revenue_management | - | - |
| oracle | communications_billing_and_revenue_management | - | - |
| oracle | communications_cloud_native_core_policy | - | - |
| oracle | communications_session_border_controller | - | - |
| oracle | communications_session_border_controller | - | - |
| oracle | communications_session_border_controller | - | - |
| oracle | communications_session_router | - | - |
| oracle | communications_subscriber-aware_load_balancer | - | - |
| oracle | communications_subscriber-aware_load_balancer | - | - |
| oracle | enterprise_communications_broker | - | - |
| oracle | enterprise_communications_broker | - | - |
| oracle | enterprise_communications_broker | - | - |
| oracle | jd_edwards_enterpriseone_tools | 9.2.6.0 | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | peoplesoft_enterprise_peopletools | - | - |
| oracle | primavera_gateway | 17.12.0 - 17.12.11 | - |
| oracle | primavera_gateway | 18.8.0 - 18.8.12 | - |
| oracle | primavera_gateway | 19.12.0 - 19.12.11 | - |
| oracle | primavera_gateway | 20.12.0 - 20.12.7 | - |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability
Impact